Jump to content

Recommended Posts

Posted

Hi all

 

Bit of an odd one.

 

Moved over to certificate based authentication for radius on Windows Server.

 

Brand new/recent/new-ish imaged laptops pick up the cert/gpo update fine and connect to Wi-Fi. These machines are getting the cert through a PDQ package as there's a Microsoft article saying sending the cert out via GPO is broke?

 

Anyway

 

Long standing laptops are struggling, mostly with

 

"Reason Code: 295 Reason: A certification chain processed correctly, but one of the CA certificates is not trusted by the policy provider."

 

Now I've been through the affected laptops, checked certs, checked NTauth and they have the same certs as the other laptops that connect fine.

 

Anyone else know whether there's another cache or check that can be made to get these laptops to connect? I feel like I'm missing something obvious.

 

Any one seen this or can help?

 

Thanks

Posted
Hi all

 

Bit of an odd one.

 

Moved over to certificate based authentication for radius on Windows Server.

 

Brand new/recent/new-ish imaged laptops pick up the cert/gpo update fine and connect to Wi-Fi. These machines are getting the cert through a PDQ package as there's a Microsoft article saying sending the cert out via GPO is broke?

 

Anyway

 

Long standing laptops are struggling, mostly with

 

"Reason Code: 295Reason: A certification chain processed correctly, but one of the CA certificates is not trusted by the policy provider."

 

Now I've been through the affected laptops, checked certs, checked NTauth and they have the same certs as the other laptops that connect fine.

 

Anyone else know whether there's another cache or check that can be made to get these laptops to connect? I feel like I'm missing something obvious.

 

Any one seen this or can help?

 

Thanks

 

Do they definitely trust the root ca?

Posted

Yeah the certificates are definitely in the root trust and had them before the old one ran out.

 

I've back to PEAP using the same cert and it all works fine.

 

I've also noticed that there's no issue with this on Windows 11 but Windows 10 only gives this error.

 

Just going to stick to PEAP for now and move to cert when I move everyone to Windows 11 over the next few months.

  • 1 year later...
Posted (edited)

 

 

On 23/08/2024 at 10:52, ITGuyNW said:

Hi all

 

Bit of an odd one.

 

Moved over to certificate based authentication for radius on Windows Server.

 

Brand new/recent/new-ish imaged laptops pick up the cert/gpo update fine and connect to Wi-Fi. These machines are getting the cert through a PDQ package as there's a Microsoft article saying sending the cert out via GPO is broke?

 

Anyway

 

Long standing laptops are struggling, mostly with

 

"Reason Code: 295 Reason: A certification chain processed correctly, but one of the CA certificates is not trusted by the policy provider."

 

Now I've been through the affected laptops, checked certs, checked NTauth and they have the same certs as the other laptops that connect fine.

 

Anyone else know whether there's another cache or check that can be made to get these laptops to connect? I feel like I'm missing something obvious.

 

Any one seen this or can help?

 

Thanks

 

Hi @ITGuyNW did you ever get to the bottom this?  Am experiencing the error "A certification chain processed correctly, but one of the CA certificates is not trusted by the policy provider." on our DCs but it seems that the clients are still connecting.

 

Am really not well up on certificates, the workstation certificate expired and was renewed earlier in the year so I thought all was good but I know Microsoft are hardening certificates in next months patches so I think I need to get this sorted or we could be without wireless soon which would be a little bit of an inconvenience.

 

Edited by mullet_man
Posted
17 hours ago, mullet_man said:

or we could be without wireless soon which would be a little bit of an inconvenience.

 

....and the understatement of the year award goes to...

  • Like 1
  • Haha 1
Posted

If I remember correctly, I ended up blowing the whole thing up from orbit and redoing it all, which meant plugging every ones laptop in to get the cert. Everything looked the same but I still feel like it was a stuck cert or something stopping everything working.

  • Haha 1
Posted
23 minutes ago, ITGuyNW said:

If I remember correctly, I ended up blowing the whole thing up from orbit and redoing it all, which meant plugging every ones laptop in to get the cert. Everything looked the same but I still feel like it was a stuck cert or something stopping everything working.

 

Ouch! Although I had to do that earlier in the year, when ours expired.

 

The issue is fixed with this reg key - applying this key and rebooting the DCs seems to have cleared the errors in the event log.

 

Windows Server: Issues with Windows Hello issue and Kerberos events caused by April 2025 updates confirmed | Born's Tech and Windows World

 

My worry was the article that suggests error ID 21  is related to the certificate hardening MS are doing.

 

Protections for CVE-2025-26647 (Kerberos Authentication) - Microsoft Support

 

Mild panic maybe averted! 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...